Privacy Policy
Last updated: 16 September 2026. Effective from that date.
1. Controller and contact
1.1 Speech To Text Tools LLC ("we", "us") is the controller of the personal data described in this policy.
1.2 All enquiries under this policy, including requests to exercise the rights in clause 9, should be sent to [email protected].
1.3 This policy applies to the website and the transcription services offered on it. It does not apply to the practices of third parties identified in clause 6.
2. Data we collect
2.1 We collect and process the following categories of data.
| Category | Description |
|---|---|
| Content | Audio and video files you upload, and the transcripts produced from them. |
| Run data | For each transcription: the providers selected, language, audio duration, channel count, the model the provider reported using, routing decisions, timings, error classifications and cost. |
| Library data | For files kept in a library: file name, format, duration, whether a video track is present, and the deletion date applied to the file. |
| Account data | Email address, display name and avatar URL supplied by Google or GitHub at sign-in; the identifier that provider uses for your account; sign-in and last-seen timestamps. |
| Billing and credit data | Credit balances and the ledger of grants, reservations and charges. Where free credits are granted or refused, the domain part of the email address concerned is recorded. |
| Technical data | IP address and browser user-agent string, recorded against your session and, where you are not signed in, against the anonymous visit. |
| Provider exchange records | The response returned by the transcription provider, as received and before processing, together with the request parameters sent. Uploaded audio is identified by a cryptographic hash and is not stored a second time. Credentials are removed before the record is written. |
| Correspondence | Email we send you, including recipient address, subject and message body, and any message you send to our contact address. |
2.2 We do not require you to create a password. We do not receive or store passwords held by the authentication providers named in clause 6.
2.3 We do not record the contents of audio files or transcripts in application logs.
2.4 As at the date of this policy we do not operate any analytics, advertising or third-party tracking technology on the website. Clause 10 applies if this changes.
3. How we use data, and on what legal basis
3.1 Where the General Data Protection Regulation or the UK GDPR applies, we process personal data for the following purposes on the following bases.
| Purpose | Legal basis | Reference |
|---|---|---|
| Providing the service: transcribing your files, storing your transcripts and library, operating your account | Performance of a contract | Art. 6(1)(b) GDPR |
| Security, fraud prevention and abuse prevention, including preventing repeated claims on free credit allowances | Legitimate interests | Art. 6(1)(f) GDPR |
| Diagnosing faults, verifying provider behaviour and substantiating published measurements | Legitimate interests | Art. 6(1)(f) GDPR |
| Service email: transcription results, file expiry notices, account notices | Performance of a contract | Art. 6(1)(b) GDPR |
| Product and marketing email | Consent, withdrawable at any time | Art. 6(1)(a) GDPR |
| Keeping accounting and transaction records | Compliance with a legal obligation | Art. 6(1)(c) GDPR |
3.2 We do not sell personal data. We do not disclose personal data for advertising purposes. We do not use your audio files or transcripts to train machine learning models of our own.
3.3 Where processing is based on consent, you may withdraw consent at any time, including by using the unsubscribe link in any marketing email. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
3.4 Where processing is based on our legitimate interests, you may object under clause 9.1(e).
4. Provider exchange records
4.1 For each transcription we retain the response returned by the transcription provider in the form in which it was received, before it is processed by our software. That response contains the transcript of your audio.
4.2 The purpose of this record is to establish whether a defective result originated with the provider or with our processing of the provider's response, to respond to disputes about a result, and to substantiate measurements we publish.
4.3 The record includes the parameters of the request sent to the provider. It does not include a second copy of your audio, which is identified by a cryptographic hash. Credentials are removed before the record is stored.
4.4 These records are retained for 14 days. Clause 5 applies.
5. Retention
5.1 We retain data for the following periods.
| Data | Retention period |
|---|---|
| Audio uploaded for a one-off transcription | 30 days from the transcription, irrespective of account status. |
| Files held in a library | Until the deletion date applied to the file. The default is 180 days from upload. You may extend it by up to 365 days at a time. On that date the file is deleted. |
| Transcripts | Until you delete them, or until the account is closed. |
| Provider exchange records | 14 days from the transcription. This period runs independently, and a record may therefore persist for up to 14 days after you delete the transcript it relates to. |
| Data of visitors who do not sign in | 7 days from the visit, after which the transcript, the audio and the technical data recorded against the visit are deleted. Associated credit ledger entries are retained without any identifier linking them to the visitor. |
| Account data after closure | Email address retained; see clause 7. All other account data is deleted on closure. |
| Credit and transaction records | Retained for the period required by applicable accounting and tax law. |
| Correspondence | Retained. |
| Database backups | Backups rotate within 30 days. Deleted data persists in backups until the backup containing it is rotated out. |
5.2 Retention periods stated as a number of days are enforced automatically. Where a period is configurable, this policy states the period in effect and is updated when it changes.
5.3 Deletion is immediate and is not reversible. We do not operate a recycle bin, a recovery window, or an archive of deleted material, subject only to the backup rotation stated in clause 5.1.
5.4 Deleting a file does not delete transcripts produced from it. Transcripts must be deleted separately.
6. Recipients
6.1 We disclose personal data to the following categories of recipient.
| Recipient | Purpose |
|---|---|
| Transcription providers: Google, Amazon Web Services, Deepgram, AssemblyAI, Microsoft Azure, Yandex and others offered on the service | Receive the audio you submit, in order to transcribe it. Only the provider you select for a given transcription receives that file. Each provider processes the file under its own terms, in the region identified by the deployment you select. |
| Cloudflare, Inc. | Object storage for uploaded audio and library files, database backup storage, and outbound email delivery. |
| Google LLC and GitHub, Inc. | Authentication, where you choose to sign in with that provider. |
| Infrastructure providers used to host the service | Hosting of the application and database. |
6.2 We disclose personal data where required to do so by law, or where necessary to establish, exercise or defend legal claims.
6.3 If our business or any part of it is transferred to another party, personal data may be transferred with it. We will notify you before any such transfer takes effect.
7. Account closure, deletion and erasure
7.1 You may delete individual transcripts and files at any time from your account. On deletion, the transcript record and the stored file are deleted, subject to clauses 4.4 and 5.1.
7.2 You may close your account at any time from your account page. On closure we delete all transcripts, all uploaded audio, all library files, your display name and your avatar URL, and we revoke all active sessions.
7.3 On closure we retain two categories of data:
(a) your email address, in order to prevent repeated claims on free credit allowances by means of repeated account creation, and in order to permit the account to be reopened by you; and
(b) the credit ledger and associated transaction records, which are financial records and are retained under clause 3.1 and for the period stated in clause 5.1.
7.4 You may request erasure of the data retained under clause 7.3 by writing to the address in clause 1.2. On such a request we will overwrite your email address, delete the link between your account and the authentication provider, and remove identifiers from the retained records, save where retention is required by law. Erasure under this clause is not reversible and the account cannot afterwards be reopened.
7.5 We will respond to a request under clause 7.4 within 30 days.
8. International transfers
8.1 Transcription providers operate in multiple regions. Each deployment offered on the service identifies the region in which it processes audio. Where you select a deployment in a region outside the European Economic Area or the United Kingdom, your audio is transferred to that region.
8.2 The region applicable to a deployment is displayed before a transcription is started. Selecting a deployment constitutes your instruction to transfer the file to that region.
8.3 Recipients identified in clause 6 may process data in the United States and in other countries. Such transfers are made on the basis of the standard contractual clauses adopted by the European Commission, or on another transfer mechanism permitted under Chapter V GDPR, as provided in our agreements with those recipients.
9. Your rights
9.1 Where the GDPR or the UK GDPR applies, you have the right to: (a) obtain confirmation of whether we process your personal data and a copy of it; (b) have inaccurate data corrected; (c) have data erased, subject to clause 7.4; (d) obtain restriction of processing; (e) object to processing carried out on the basis of legitimate interests; and (f) receive data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
9.2 Rights may be exercised in whole or in part from your account page, and otherwise by writing to the address in clause 1.2. We will respond within 30 days. We may extend that period by two further months where necessary, and will tell you if we do.
9.3 You have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement.
9.4 We do not charge a fee for exercising these rights, except as permitted by law.
10. Cookies
10.1 We set two cookies, both strictly necessary for the operation of the service: one maintains your signed-in session, and one identifies an anonymous visit so that work started before sign-in remains available to you afterwards.
10.2 Both cookies contain a random value only. They are marked HttpOnly and are not readable by scripts. They are not used to track you across other websites.
10.3 We do not currently set analytics or advertising cookies. If we do so in future, we will update this policy and, where consent is required by law, obtain your consent before any such cookie is set.
11. Security
11.1 We apply technical and organisational measures appropriate to the risk, including transport encryption, restriction of access to stored content to the account that owns it and to personnel who operate the service, and storage of session tokens in hashed form only.
11.2 No method of transmission or storage is entirely secure, and we do not warrant absolute security.
11.3 Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you, within the periods prescribed by law.
12. Children
12.1 The service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, write to the address in clause 1.2 and we will delete it.
13. Changes to this policy
13.1 We may amend this policy at any time. The version published on this page is the version in force, and an amendment takes effect when it is published here. The date at the head of this policy states when the current version was published.
13.2 Your continued use of the service after an amendment is published constitutes acceptance of the amended policy.
13.3 Where an amendment materially reduces the protections applying to data already collected, including the addition of a new category of recipient or of tracking technology, we will notify account holders by email to the address held on the account before the amendment takes effect.
13.4 It is your responsibility to review this page periodically.